Sophos has announced Exploit Path Verification (EPV), a new feature that will be integrated into Sophos Managed Risk to help security teams better prioritize and manage exploitable vulnerabilities in their environment. The tool’s operability will be developed with OpenAI’s GPT cyber models through the Daybreak Defense Network, in order to offer verified and evidence-backed verdicts that provide security managers with the clarity necessary to fix the most important vulnerabilities first.

Security teams face a growing gap between the vulnerabilities they can detect and those they can fix. The scanners detect thousands of vulnerabilities and severity scores and classify them. However, a severity score does not allow you to determine whether a critical breach is protected by a control that blocks it, or whether two low-severity findings are linked along the path that leads to a security breach.

As a result, security teams often apply patches based on a generic score, rather than considering whether an attacker could access and exploit a flaw in their specific environment.

Analyze asset and patch status

Sophos is designing EPV to close that gap. Its development focuses on analyzing asset and patch status, endpoint protection policy, network accessibility, identity and privilege data, and the availability of known exploits, then providing a clear, evidence-backed verdict on exploitability.

EPV identifies chained paths where multiple lower severity findings are combined into a single exploitable path, evaluates whether a control blocks a technique class or just a public proof of concept, and writes fix text ready for inclusion in an issue review.

This functionality will have a consultative and complementary nature by design. Each verdict is labeled as AI-generated, with its evidence visible, and Sophos analysts review the results.

“One of the most common challenges facing security teams today is the volume of findings they must review and the lack of clarity about which are the most important, or in other words, which expose you to the greatest risk,” said John Peterson, Chief Technology Officer at Sophos. “Exploit Path Verification is being developed to make it clear which parts of your environment are accessible to an attacker, with the evidence to prove it, so they can fix what really matters first.”

EPV expands Sophos collaboration with OpenAI. Through the OpenAI Daybreak Defense Network (previously known as the OpenAI Daybreak Cyber ​​Partner Program), which Sophos joined in June 2026, the company incorporated cutting-edge cyber models into MDR investigations, advisory assessments, and workflows that help customers detect, validate, and remediate vulnerabilities.

EPV will build on that work within a product that customers already use. OpenAI’s GPT cyber models provide cutting-edge reasoning to help assess vulnerability. Sophos provides environment-specific testing and product controls, and its analysts review the results delivered to customers.

“Our goal through the OpenAI Daybreak Defense Network is to give defenders the advantage of cutting-edge AI, securely,” said McCall McIntyre, Head of Global Cyber ​​Alliances at OpenAI. “Sophos has been a very involved partner since joining the program, and Exploit Path Verification is a clear example of cutting-edge thinking applied to a real defensive problem, with the security measures that responsible implementation demands.”